Select the type of tool this is related to
Tell us about your request
A read-only, fully automated operational-review skill for Amazon FSx for NetApp ONTAP (FSxN) that assesses a file system / SVM / volume (or a whole account+region footprint) across Backup, Observability, Operations, Performance, and Security, and returns a prioritized, evidence-based findings report.
Which AWS service(s) is this for?
Amazon FSx for NetApp ONTAP, Amazon CloudWatch, AWS Backup, Amazon EC2
What problem are you trying to solve?
Operators running FSx for NetApp ONTAP have no quick, consistent way to assess the operational posture of their file systems. Doing it by hand means stitching together fsx config, CloudWatch metrics, AWS Backup coverage, and EC2 networking, and knowing FSxN-specific gotchas (e.g. Gen2 file systems don't emit StorageCapacityUtilization; SVM root volumes skew capacity metrics). Without a skill, DevOps Agent gives a generic review that misses these service-specific details and isn't reproducible across prod/pre-prod or across iterations.
How should it behave?
Triggers on requests like "FSxN operational review", "review my FSx ONTAP", "audit my FSxN posture". Self-discovers all ONTAP file systems in the account/region, runs 46 checks across 5 pillars using only public AWS Describe*/List*/Get* calls and CloudWatch metric reads via use_aws, applies evidence guardrails (missing data → "Not evaluated", never a guessed pass/fail), and produces a prioritized findings report keyed to check IDs. Strictly read-only — no Create*/Update*/Delete*, no ONTAP CLI, no manual steps.
Which DevOps Agent functionalities is this relevant to?
Chat tasks, Evaluation
Does this need extra permissions?
Yes — read-only only: fsx:Describe* + fsx:ListTagsForResource, cloudwatch:DescribeAlarms/GetMetricData/GetMetricStatistics/ListMetrics, backup:ListProtectedResources/ListRecoveryPointsByResource, ec2:DescribeSecurityGroups/Subnets/RouteTables. Delivered via the shared
devops-agent-skill-policies.yaml under a new EnableAwsFsxnOperationsReview toggle.
Are you currently working around this?
Manual, service-specific checklists and ad-hoc CloudWatch/console inspection — slow, inconsistent, and not reproducible.
Have you checked for existing tools?
Would you like to build it?
Additional context
PR up at #117. Not a duplicate of aws-backup-coverage-review — that reviews account-wide AWS Backup coverage; this is an FSxN-specific review across five pillars.
Select the type of tool this is related to
Tell us about your request
A read-only, fully automated operational-review skill for Amazon FSx for NetApp ONTAP (FSxN) that assesses a file system / SVM / volume (or a whole account+region footprint) across Backup, Observability, Operations, Performance, and Security, and returns a prioritized, evidence-based findings report.
Which AWS service(s) is this for?
Amazon FSx for NetApp ONTAP, Amazon CloudWatch, AWS Backup, Amazon EC2
What problem are you trying to solve?
Operators running FSx for NetApp ONTAP have no quick, consistent way to assess the operational posture of their file systems. Doing it by hand means stitching together fsx config, CloudWatch metrics, AWS Backup coverage, and EC2 networking, and knowing FSxN-specific gotchas (e.g. Gen2 file systems don't emit StorageCapacityUtilization; SVM root volumes skew capacity metrics). Without a skill, DevOps Agent gives a generic review that misses these service-specific details and isn't reproducible across prod/pre-prod or across iterations.
How should it behave?
Triggers on requests like "FSxN operational review", "review my FSx ONTAP", "audit my FSxN posture". Self-discovers all ONTAP file systems in the account/region, runs 46 checks across 5 pillars using only public AWS Describe*/List*/Get* calls and CloudWatch metric reads via use_aws, applies evidence guardrails (missing data → "Not evaluated", never a guessed pass/fail), and produces a prioritized findings report keyed to check IDs. Strictly read-only — no Create*/Update*/Delete*, no ONTAP CLI, no manual steps.
Which DevOps Agent functionalities is this relevant to?
Chat tasks, Evaluation
Does this need extra permissions?
Yes — read-only only: fsx:Describe* + fsx:ListTagsForResource, cloudwatch:DescribeAlarms/GetMetricData/GetMetricStatistics/ListMetrics, backup:ListProtectedResources/ListRecoveryPointsByResource, ec2:DescribeSecurityGroups/Subnets/RouteTables. Delivered via the shared
devops-agent-skill-policies.yaml under a new EnableAwsFsxnOperationsReview toggle.
Are you currently working around this?
Manual, service-specific checklists and ad-hoc CloudWatch/console inspection — slow, inconsistent, and not reproducible.
Have you checked for existing tools?
Would you like to build it?
Additional context
PR up at #117. Not a duplicate of aws-backup-coverage-review — that reviews account-wide AWS Backup coverage; this is an FSxN-specific review across five pillars.